Exposed Directory Reveals FortiGate and MeshCentral Intrusion Targeting Thai Broadband Provider

· Original article ↗

Summary

An exposed directory revealed an intrusion targeting 3BB, including exploitation of FortiGate CVE-2024-21762, MeshCentral persistence, connected agents, credential-harvesting tools, and evidence of root-level access.

Key points

  • Hunt.io found 298 files in an exposed directory containing exploit scripts, credentials-related tools, persistence mechanisms, and an inventory of compromised devices.
  • The scripts show exploitation of FortiGate SSL-VPN CVE-2024-21762 at mail.3bb.co.th, with a reverse-shell callback to the staging server.
  • MeshCentral was configured for persistence under the TH-3BB group; the device inventory showed multiple connected agents running with root privileges.
  • Artifacts indicate root-level compromise of an internal Linux server and reconnaissance and lateral-movement activity across 3BB systems.
  • Scripts targeted RADIUS databases for credential extraction; the directory also contained a Triple T Broadband OpenVPN certificate and active session tokens for Jasmine-branded systems.
  • A cleanup script was prepared to erase logs and exploitation artifacts while preserving MeshCentral access.
  • The report recommends patching FortiGate appliances, auditing unauthorized MeshCentral agents and access, rotating potentially exposed credentials, and preserving forensic evidence.

Article Details

Attack Vectors
  • The actor fingerprinted the 3BB FortiGate SSL-VPN, tested several vulnerabilities, and prepared a CVE-2024-21762 exploit that used a crafted chunked HTTP request, heap spraying, and a ROP chain to launch a reverse shell.
  • Scripts attempted credential brute-forcing against the FortiGate VPN and 3BB agent portal, and SSH password spraying against more than 55 internal hosts.
  • The actor probed the agent portal for session forgery, file-upload weaknesses, SQL injection, path traversal, open redirects, and HTTP request smuggling.
  • Scripts probed an F5 BIG-IP appliance for known vulnerabilities and targeted an internal Pentaho server with a Ghostcat file-disclosure exploit.
  • Post-compromise tooling prepared PwnKit and Dirty COW privilege escalation, harvested keys and credentials, targeted RADIUS databases, and used MySQL file operations to deploy web shells and inject SSH keys.
  • The actor deployed MeshCentral for persistent remote access and prepared a cleanup script to remove logs and exploitation artifacts while retaining persistence.
Defensive Notes
  • Check FortiGate SSL-VPN exposure to CVE-2024-21762 and update appliances to supported, fully patched firmware.
  • Review VPN accounts, configuration changes, authentication attempts, and administrative activity for unauthorized access.
  • Audit MeshCentral installations for unauthorized agents, unexpected WebSocket connections, and unapproved management servers.
  • Rotate potentially exposed SSH keys, database passwords, VPN certificates, RADIUS credentials, and application secrets.
  • Review RADIUS servers, VPN services, and identity systems for unauthorized access or credential extraction.
  • Hunt for hidden SUID binaries, web shells, SSH key changes, unauthorized scheduled tasks, and newly installed remote-management software.
  • Preserve forensic evidence before remediation when compromise is suspected; the recovered cleanup script was designed to erase logs and artifacts.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEwww[.]ayuthayatech[.]comActor-designated MeshCentral management and C2 server for deployed agents.
IPV492[.]63[.]180[.]133Attacker VPS hosting the exposed operational toolkit and serving as the CVE-2024-21762 exploit's reverse-shell callback host.

MITRE ATT&CK

T1021.004 · SSHScripts attempted SSH access across internal hosts, including attempts using stolen IDC keys.T1068 · Exploitation for Privilege EscalationThe toolkit prepared PwnKit and Dirty COW exploits to obtain root privileges on Linux hosts.T1070.002 · Clear Linux or Mac System Logscleanup_target.sh was designed to delete Linux system and service logs while preserving the installed MeshCentral agent.T1070.003 · Clear Command Historycleanup_target.sh cleared user shell histories to conceal activity.T1078 · Valid AccountsThe recovered toolkit attempted SSH access using stolen IDC keys and included a corporate OpenVPN client certificate whose continued validity was unconfirmed.T1098 · Account ManipulationThe MySQL exploitation scripts included SSH key injection and modification of database privileges to expand or retain access.T1110.001 · Password GuessingScripts tried username and password combinations against the 3BB FortiGate VPN and agent portal.T1110.003 · Password SprayingThe brute.sh, brute2.sh, and brute3.sh scripts performed SSH password spraying against more than 55 internal hosts.T1190 · Exploit Public-Facing ApplicationThe recovered CVE-2024-21762 exploit targeted the public-facing FortiGate SSL-VPN to execute a reverse shell.T1219 · Remote Access ToolsThe actor deployed MeshCentral agents for persistent remote administration of compromised systems.T1505.003 · Web ShellScripts used MySQL INTO OUTFILE to deploy PHP web shells on targeted servers.T1552 · Unsecured Credentialscred_hunt.sh searched compromised hosts for SSH private keys, PHP configuration files, database credentials, SNMP community strings, and shell history.T1574.006 · Dynamic Linker HijackingThe PwnKit payloads used GCONV_PATH hijacking to execute commands with root privileges.T1595 · Active ScanningThe actor probed FortiGate SSL-VPN endpoints and fingerprinted the appliance and firmware before exploitation.

CVE

CVE-2016-5195dcow.cExploitDirty COW (CVE-2016-5195) privilege escalation via /etc/passwd overwrite.CVE-2018-13379through /remote/hostcheck_validate), CVE-2023-27997 (XORtigate pre-authentication heap overflow), CVE-2018-13379 (path traversal via fgt_lang?lang=/../../../../etc/passwd), and CVE-2024-21762, indicating that theCVE-2020-1938ghostcat.pyExploitExploitation of CVE-2020-1938 (Ghostcat) for AJP file disclosure against an internal Pentaho server.CVE-2021-22986f5_test.sh, f5_2.shRecon / ExploitEnumeration and exploitation of F5 BIG-IP vulnerabilities (CVE-2021-22986, CVE-2022-1388, and CVE-2023-46747).CVE-2021-4034evil.c, evil2.c, evil3.cExploitShared library payloads for exploiting PwnKit (CVE-2021-4034).CVE-2022-1388f5_test.sh, f5_2.shRecon / ExploitEnumeration and exploitation of F5 BIG-IP vulnerabilities (CVE-2021-22986, CVE-2022-1388, and CVE-2023-46747).CVE-2022-42475known FortiGate vulnerabilities rather than focusing on a single exploit. The script probes for CVE-2022-42475 (heap overflow through /remote/hostcheck_validate), CVE-2023-27997 (XORtigate pre-authentication heapCVE-2023-27997exploit. The script probes for CVE-2022-42475 (heap overflow through /remote/hostcheck_validate), CVE-2023-27997 (XORtigate pre-authentication heap overflow), CVE-2018-13379 (path traversal viaCVE-2023-46747f5_test.sh, f5_2.shRecon / ExploitEnumeration and exploitation of F5 BIG-IP vulnerabilities (CVE-2021-22986, CVE-2022-1388, and CVE-2023-46747).CVE-2024-21762The threat actor used CVE-2024-21762 to target a FortiGate 60F SSL-VPN at mail.3bb.co[.]th.

Vendors

Products

Tools

Countries

Industries

Related Articles